ResourcesTexas Breach Tracker › UTMB Health (Galveston)
Healthcare Ransomware Remediated

UTMB Health (Galveston)
Breach Analysis

UTMB Health at Galveston disclosed a ransomware event in July 2024 affecting administrative and clinical systems. Approximately 420,000 patient records were identified in scope after forensic investigation.

Incident Date
2024-07-22
Records Exposed
420,000
Attack Type
Ransomware
Threat Actor
Unconfirmed

How they got in

Compromised vendor remote access account used to gain foothold. Ransomware deployed across administrative and clinical networks — suggesting insufficient segmentation between vendor access zone and patient data systems.

Sentinel / Fortress / Command coverage

Sentinel Vendor remote access monitoring: anomalous session time, volume, or lateral movement triggers immediate SOC alert and session suspension
Fortress JIT vendor access: vendors receive time-limited, scoped access — no persistent credentials usable outside approved window
Command HIPAA BAA and vendor risk assessment: vendor remote access requirements documented and enforced contractually

Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →

Regulatory exposure

Regime Standard / Citation Gap Identified
HIPAA 45 CFR §164.308(b) Business associate management — vendor remote access lacked documented security requirements
HIPAA 45 CFR §164.312(a) Access control — vendor access to PHI-containing systems not scoped to minimum necessary
TDPA Tex. B&C Code §521.053 420,000 TX patient notifications required

5-point hardening list

CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.

Is your organization hardened against this attack vector?

Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.